Seatext library / BotRefund evidence

How to Avoid Blocking Broad Geographies Based on Few Records

Don't block entire countries or regions because of a handful of suspicious leads. Use multi-signal behavioral analysis — combining session behavior, CRM outcomes, placement patterns, and device data — to verify fraud before excluding...

Built for advertisers who need clear, refund-ready traffic evidence.

Blocking a whole country because three leads from that region looked suspicious is a costly over-correction. Legitimate customers travel, use VPNs, work from corporate networks, or live in regions that also host botnets. The fix is not to ignore geography — it is to treat geography as one signal among dozens, then require corroboration before you exclude.

Start with a structured audit that compares ad-platform data, website sessions, and CRM outcomes. Look for repeatable technical and behavioral patterns: unusually fast form completion, identical field structures, sudden placement-level spikes, or conversion events with no meaningful page engagement. When several independent signals point to the same sessions, you have evidence. When only the country code looks odd, you have a hypothesis — not a verdict.

Why Single-Signal Blocking Fails

Geo-IP data is coarse. A single IP range can serve a corporate office, a university, a coffee shop, and a residential block. VPNs, proxies, and mobile gateways routinely exit in countries the user never visited. Privacy tools, travel, and unusual devices all produce unexpected geographic signals for genuine people.

BotRefund's detection philosophy treats every anomaly as evidence, not a verdict. Their system runs 106 independent checks — browser consistency, pointer behavior, scroll dynamics, timing, rendering quirks — and only flags a visit when multiple signals align. A lone country-code anomaly never triggers a block.

Advertisers who block on geography alone typically see two outcomes: legitimate lead volume drops, and the bot operators simply rotate to a new exit node. The fraud persists; the real audience shrinks.

The Multi-Signal Investigation Framework

Replace "block country X" with a repeatable workflow that weighs geography alongside behavioral, technical, and outcome data.

  1. Preserve attribution before changing anything. Keep campaign, ad set, creative, placement, and click identifiers intact while you investigate. Pausing or rewriting targeting destroys the trail you need to prove invalid traffic to Meta or Google.
  2. Pull three data layers. Ad-platform reports (placement, creative, audience expansion, device), website session data (scroll depth, dwell time, pointer paths, form interaction timing), and CRM outcomes (contactability, qualification, repeat engagement).
  3. Segment by the suspicious geography. Compare the suspect region against your baseline across every dimension: contactability rates, session behavior distributions, placement mix, creative performance, device mix, hour-of-day patterns.
  4. Look for clusters, not outliers. A single fast form submit is noise. Ten fast submits from the same placement, same creative, same hour, all with zero scroll and identical pointer paths — that is a cluster.
  5. Require at least two independent signal families. Geography + behavior. Placement + CRM outcome. Device + timing. One family is never enough.
  6. Document the evidence bundle. Export a readable report that ties each flagged session to a click ID, timestamp, placement, and the specific behavioral signals that triggered the flag. This is what ad reps accept for refund claims.

Step-by-Step Process: From Suspicion to Verified Exclusion

1. Define the trigger

Set a quantitative threshold that opens an investigation — e.g., "contactability below 20% for any geography with ≥20 leads in 7 days." This prevents gut-feel reactions.

2. Run the three-layer comparison

Ad platform → website → CRM. If the geography shows normal scroll depth, varied dwell times, human-like pointer movement, and the CRM shows qualified opportunities, the geography is fine. The problem is likely a specific placement or creative.

3. Isolate the placement or audience expansion

Meta's audience expansion and partner inventory often introduce low-intent or automated traffic. Compare lead quality with expansion on vs. off. Compare Facebook Feed vs. Instagram Reels vs. Audience Network. The geography may be a red herring.

4. Apply behavioral suppression, not geographic exclusion

If the cluster is real, suppress the conversion events for the specific behavioral signatures (e.g., sub-500ms form submits, zero-scroll sessions, grid-aligned pointer paths). This trains the ad platform's optimizer on verified humans without cutting off a region.

5. Verify the optimizer adapts

Watch cost per qualified lead and contactability for 7–14 days. If they improve, the suppression worked. If they don't, the fraud pattern has shifted — reopen the investigation.

6. Escalate to refund claim only with a complete evidence bundle

BotRefund's case study with FinTrust recovered $140,000 by suppressing conversion events for automated browser emulation signals, ensuring Facebook and Google AI trained only on verified accounts. The refund claim succeeded because the evidence tied each suppressed event to a click ID and behavioral proof.

Key Signals That Distinguish Bots from Real Users

Geography is a weak signal. These are stronger, especially in combination:

  • Contactability: Disconnected numbers, invalid email domains, repeated addresses, unusual concentration of one country code.
  • Timing: Several leads arriving in short bursts, forms submitted immediately after landing, conversions concentrated at unusual hours.
  • Session behavior: No scrolling, no field corrections, uniform click paths, no meaningful time on the offer page.
  • Campaign patterns: Sharp lead-quality difference by placement, creative, audience expansion, device, or landing page.
  • CRM outcome: High reported lead count paired with no calls connected, demos booked, qualified opportunities, or repeat engagement.
  • Biometric & behavioral checks: Scrollbar width leaks, clean-context iframe mismatches, ghost click detection, honeypot trap interactions, robotic linear mouse movements, absence of humanlike mouse tremor, superhuman input speed (<1ms), grid-aligned movement patterns, unnatural session durations.

No single signal proves fraud. A consistent cluster across browser, network, device, and behavior evidence is what supports a high-confidence investigation.

Common Mistakes and How to Avoid Them

MistakeWhy It HurtsBetter Approach
Blocking a country after 3–5 bad leadsLegitimate users share exit IPs; botnets rotate geography dailyRequire ≥2 independent signal families and a documented cluster before any exclusion
Treating all unresponsive contacts as fraudWeak campaigns attract real people not ready to buy; excludes valuable audienceCompare ad-platform data, website sessions, and CRM outcomes before changing targeting
Relying on server-side IP reputation aloneMisses advanced botnets using residential proxies; flags corporate VPNsAdd client-side behavioral auditing (pointer, scroll, timing, rendering checks)
Pausing campaigns to "stop the bleeding"Destroys attribution needed for refund claims; loses legitimate volumePreserve attribution, suppress specific conversion events, keep campaigns running
Using security logs instead of marketing-ready reportsAd reps cannot review raw security data; claims get rejectedExport readable reports tied to click IDs, placements, timestamps, and behavioral evidence

When Geographic Exclusion Actually Makes Sense

Exclude a geography only when:

  • You have a documented cluster of ≥2 independent signal families consistently flagging sessions from that region.
  • The cluster persists across multiple placements, creatives, and days — ruling out a single bad publisher.
  • Legitimate traffic from that region is near zero (e.g., you don't ship there, don't support the language, have no sales coverage).
  • You have tested behavioral suppression first and the fraud pattern is geography-locked (rare).

Even then, use a target exclusion in the ad platform rather than a firewall block. Target exclusions are reversible, auditable, and don't break attribution for other regions.

Limitations and Edge Cases

  • Low-volume campaigns: Statistical clusters need minimum sample sizes. With <50 leads per week, you may not reach confidence. Extend the lookback window or aggregate across similar campaigns.
  • New markets: Baseline behavior is unknown. Run a 2–4 week learning phase with behavioral monitoring only — no exclusions — before setting thresholds.
  • Privacy tools and corporate networks: Legitimate users on hardened browsers, VPNs, or zero-trust networks can trigger individual behavioral checks. Cross-checking across 106 signals prevents false positives, but expect a higher "review" queue.
  • Sophisticated human fraud farms: Real people paid to fill forms will pass behavioral checks. CRM outcome signals (contactability, qualification) become the primary discriminator.
  • Platform policy changes: Meta and Google update invalid-traffic definitions. Keep your evidence format portable so you can re-map signals when policies shift.

Key Facts

FactDetailSource
BotRefund detection vectors106 independent checks across browser, network, device, and behaviorS4, S7
Reported accuracy99% when session evidence supports itS4, S7
Primary signal familiesContactability, timing, session behavior, campaign patterns, CRM outcomeS1
Behavioral checks examplesScrollbar width leak, clean context iframe, ghost click, honeypot trap, pointer behavior, motion behavior, speed behavior, path behavior, engagement behaviorS2, S4, S7, S9
FinTrust case study recovery$140,000 refunded, 14% average bot click rate, +18% conversion rate increaseS6
Refund approval rate83% across client refund claims submitted to ad platformsS2
Setup time~1 minute to add BotRefund to a websiteS2
Historical refund reachGoogle Ads spend dating back to 2017S2

Terminology

  • Invalid traffic (IVT): Clicks or impressions not resulting from genuine user interest — includes accidental clicks, automated tools, bots, competitor click fraud, and impression fraud.
  • Pixel poisoning: When bot conversions train the ad platform's optimizer to find more bots, degrading lead quality over time.
  • Client-side audit: Behavioral analysis running in the visitor's browser (pointer, scroll, timing, rendering) — catches advanced botnets that server-side IP logs miss.
  • Server-side audit: Analysis of server logs (IP, headers, user-agent) — catches basic scrapers but struggles with residential proxies and human fraud farms.
  • Click ID (GCLID/FBCLID): Unique identifier appended to landing-page URLs by Google/Meta — essential for tying a session to a specific paid click for refund claims.
  • Behavioral suppression: Preventing specific conversion events from firing based on behavioral evidence, so the ad platform's optimizer trains only on verified humans.
  • Evidence bundle: A readable report linking each flagged session to click ID, timestamp, placement, and the specific behavioral signals that triggered the flag.

FAQ

How many suspicious leads from one country justify an investigation?

Set a quantitative trigger — e.g., contactability below 20% for any geography with ≥20 leads in 7 days. Three leads is never enough; it's noise.

Can I just use Cloudflare or a WAF to block bad countries?

Edge tools block at the network layer. They cannot see post-click behavior, preserve click IDs, or produce marketing-ready refund reports. They also block legitimate users sharing exit IPs. Use them for DDoS/WAF needs; add a marketing-layer behavioral auditor for ad-quality work.

What if the bot traffic looks human — real people paid to fill forms?

Human fraud farms pass behavioral checks. Your discriminator shifts to CRM outcomes: contactability, qualification rates, repeat engagement. If leads never progress in your funnel, suppress the conversion events for that placement/audience regardless of geography.

How long should I monitor before deciding to exclude a geography?

Minimum 7–14 days after applying behavioral suppression. Watch cost per qualified lead and contactability. If they improve, the suppression worked. If not, the pattern has shifted — reopen the investigation.

Will suppressing conversion events hurt my campaign's learning phase?

No. Suppressing invalid events improves signal quality. The optimizer learns from verified humans instead of polluted data. FinTrust saw an 18% conversion rate increase after suppressing automated browser emulation signals.

What evidence do Meta and Google actually accept for refunds?

Readable reports tied to click IDs (GCLID/FBCLID), timestamps, placements, and specific behavioral signals. Raw security logs get rejected. BotRefund's 83% approval rate comes from formatting evidence the way ad reps expect.

Do I need to block the geography in my firewall too?

No. Ad-platform target exclusions are sufficient for paid traffic. Firewall blocks affect organic, direct, and referral traffic — and they break attribution for future investigations.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more